ClickUp Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants
ID: 82e14299-b831-5f06-85a9-46f96c9c58f1
STIX ID: report--82e14299-b831-5f06-85a9-46f96c9c58f1
Feed Name: Cyber Press
Threat Score
**Executive summary:** ClickUp exposed a hardcoded Split.io API token in its production JavaScript bundle, allowing unauthenticated access to backend data (including ~959 email addresses from Fortune 500 and government entities), and a webhook SSRF flaw that the researcher used to retrieve AWS IAM credentials; the vulnerabilities reportedly persisted for over a year despite prior reports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
